Sun IdM 7.1 - 'Is Disabled' shows 'No' for disabled user in configurator UI

Hi All,
I have user1 in SIM who has been disabled on RACF through SIM.
But, when I open this user obejct in SIM, logged in as configurator, the 'Is Disabled' column for the RACF resource shows 'No', when it should be showing 'Yes'.
I've checked user1 on RACF and user1 has been disabled there.
Below is the code which I've used to disable the user on RACF:
             <set>
                <concat>
                  <s>view.update.accounts[</s>
                  <ref>appname</ref>
                  <s>].selected</s>
                </concat>
               <s>true</s>
            </set>
          <set>
            <concat>
              <s>view.waveset.accounts[</s>
              <ref>appname</ref>
              <s>].disabled</s>
            </concat>
            <s>true</s>
          </set>
          <set>
            <concat>
              <s>view.accounts[</s>
              <ref>appname</ref>
              <s>].disabled</s>
            </concat>
            <s>true</s>
          </set>
            <set>
            <concat>
              <s>view.accounts[</s>
              <ref>appname</ref>
              <s>].disable</s>
            </concat>
            <s>true</s>
          </set>(In the above code, the 'appname' variable will contain the value as 'RACF' at run-time).
I've tried various other things, but still the 'Is Disabled' column shows 'No' only.
Also, apart from the above code, I'm also using resource action which actually runs the RACF command to disable the user on RACF.
FYI - I'm using Sun Identity Manager 7.1
Any help on this would be greatly appreciated.
Thanks in advance!

Check if you have customized
'Default RACF ListUser AttrParse', if so it should have the attribute
*<multiLine>*
*<t> ATTRIBUTES=</t>*
*<str name='ATTRIBUTES' multi='true' delim=' ' noval='NONE'/>*
*<skipToEol/>*
Reason:
Since this is the attribute reference in the method isDisabled() in your com.waveset.adapter.RACFResourceAdapter.
Thanks

Similar Messages

  • Showing portlet for anonymous user on Sun Java System Portal 2004Q2

    Hi to all,
    How can i show my portlet(JSR168) on Sun Portal server for anonymous users with saved preferences?
    waiting for ur productive reply
    ~Neeraj S.
    [email protected]

    Neeraj,
    What do you mean by "anonymous users with saved preferences"?
    The anonymous desktop does not contain any editable functionality. Remember, the anonymous desktop is shared by all users that are not logged in. Therefore, it does not make sense to allow anonymous users to modify the display profile. Notice that there are no edit/minimize/maximize/remove buttons on any of the channels on the anonymous desktop. This is because the anonymous user has a specific DP that removes these buttons.
    Add a portlet to the desktop just like any other channel. This can be done directly to the anonymous user's DP. Add the channel and remove the edit/minimize/maximize/remove buttons.
    Users can modify the portlet preferences once they log in to their own account. At this point the preferences will be stored with their own DP.
    HTH,
    Jim

  • Request Offerings not showing up for custom User role in SMPortal

    Hello All,
    I've created a custom End User role and scoped it to the domain users group.
    To this role I want to show a specific set of Request Offerings on the portal
    For that Purpose I created a new Service Offering and added these Request Offerings to it.
    I then went on to create a Catalog Group and added the Service Offering to it.
    I then created the custom user role based on the EndUser role and allowed them to see all Forms, all Queues, All CI's and on the Catalog group I select that they could only see the Catalog Group which I just created.
    I then logged in into the SMPortal and was expecting that my Service Offering would be shown to them.
    However, they don't see the service offering.
    What could cause this?
    Is there something I'm missing?
    Thanks in advance!
    Filip

    You have to add the Service Offerings and the Request Offerings in the Catalog Group. Nesting doesn't work because Service Offerings and Request Offerings are different types of objects.
    This offers the option the manage the access to Service Offerings and Request Offerings very granular if needed. For instance you can control access to a Service Offering in one Catalog Group related to one user role (A) and use two additional Catalog Groups
    with different Request Offerings related to other user roles (B) and (C). Result will lead to:
    User in Role A and B -> Can see Service Offerings A containing Request Offerings B
    User in Role A and C -> Can see Service Offerings A containing Request Offerings C
    User in Role A, B and C -> Can see Service Offerings A containing Request Offerings B and C
    User in Role A only -> Don's see anything because of the missing permission on any Request Offering. So the "empty" Service Request won't show up in the portal.
    Hope his helps.
    Andreas Baumgarten | H&D International Group

  • Eu_role not showing up for all users in EP7

    Hi SDN,
    I have newly deployed EP7, I want all users to have EU_Role but but its not showing up even though i have added eu_role to everyone group.
    i do see eveyone group attched to all users but it does not show up eu_role to it.
    Am i missing anything in  EP7 Configuration.
    Thanks
    DK

    Hi,
    Go to everyone group and click the tab 'assign role'
    Search for the eu_role recursively(check the box recursive before search). otherwise all roles will not show up.
    Hope that helps you
    Raghu

  • Weird issue - invisible folders/shares showing up for one user

    I've *never* seen this happen before. One of our users, when using Illustrator, goes to open or save a file. In his file browsers, invisible shares keep appearing. If I unmount his network shares, the problem disappears. I just re-installed his system and that had no effect (archive and re-install). He's run into issues because he'd save files in what appears to be a MIRROR image of a network share and no one else can find his files.
    I found something online that said to remove aliases from the /Network folder but I can't seem to delete the two entries....grrr
    Here's a screenshot:
    http://www.cttechies.com/ghostfolders.png

    Well, I'm not certain, but I think, (lest things have changed), that some of the stuff from System Prefs & User Prefs go into reconstructing those invisible Folders/Files.
    If you boot it into FWTDM you might try trashing those Invisibles, (automount & Servers) at root of that machine, as well as...
    /Users/nnnn/Library/Preferences... the whole Prefs folder there.
    /Library/Preferences/SystemConfiguration... the whole SysConfig folder.
    /Library/Preferences/com.apple.sharing.firewall.plist
    /Library/Preferences/com.apple.AppleFileServer.plist
    /Library/Preferences/com.apple.networkConfig.plist
    Reboot... of course you dont have to trash them, you can just move them to the desktop to drag back if it doesn't work.
    BTW, though there are many, I use Xupport...
    http://www.xupport.ch/
    to make the Finder show "invisibles" so I can GUI get rid of that stuff... along with it's Force Delete or whatever it's called.

  • Showing updates for wrong user

    At some point my girlfriend signed into the Mac App store on my computer. Now it refuses to show my updates and only shows hers ( and asks for her log in credentials to install them of course). If I go to the actual App Store page, it is clear that it is ME that is logged in and not her. And I can additionally log out and log in a million times but nothing refreshes the app update list (I have also hit command-R to manually refresh the updates page, and I see it refreshing, but still shows *her* apps). Is there some way to blow away the App Store's state so I can get my updates back?

    1. Will that affect the updates list? (i.e. why is it choosing to arbitrarily show her updates instead of mine if its the case that I have a computer with apps from both accounts)
    2. I don't think I have any apps with her info, but I guess I could be wrong (especially if that is for sure what causes this behavior). If that's the case, is there a utility that will point out "her" apps to me so I know which they are, because again I have no idea which they are.

  • Some asset classes do not show up for a user in S_ALR_87011990

    Hi
    When the asset history sheet is run in S_ALR_87011990, a user is unable to display some asset classes in the report. This was referred to security team. They say that everything looks fine and nothing appears wrong for that user--roles and profiles ok etc.,. No worklists are being used and no variants are being used. No dynamic selections either.
    Can someone let me know why the user is unable to display some asset classes. Asset classes that the user is unable to display were created last year. Most users are able to display these asset classes in the report except this user.
    Please  help and provide some exact solution.
    Best wishes
    Rajmohan..

    Hi Rajmohan,
    most probably it is a authorization problem.
    Please compare the assets which are not shown with this user. It could be a cost center.
    regards Bernhard

  • How to show inboxs for multiple users?

    I recently have started using the Mail App on my iMac. I was using my company's OWA as my standard mail program but I found the Mac mail easier to use. But... In my OWA it was possible for me to have multiple accounts and inboxs from the same server (exchange 2007) and after I had set up my mac mail with my primary exchange account, I couldn't send or recieve from my other accounts. Then I saw that I could type in more e-mail addresses in the Account setup and now it is possible for me to send fromthese accounts.
    But still.. I can't see the incoming mails for these accounts. Anybody who knows how to setup mac mail app so I can see the incoming mails for ohter users than my primary?

    I've found the same problem in OS X Lion, with Mail, iCal and Address Book getting confused when two Exchange accounts on the same server are configured, resulting in either missing or duplicate entries (despite everything appearing fine when accessing the accounts individually via Outlook or OWA).  iOS doesn't have any problem with this setup; two Exchange accounts on the same server work perfectly; the issue seems specific to Mac OS X.
    After some experimentation I've found a workaround.  Since the issue crops up with two Exchange accounts on the same server, it seems possible to trick OS X into thinking the accounts are on two separate servers through a little DNS manipulation (which I realize may not be a practical option for everyone).  Here's what resolved the issue for me:
    My external and internal DNS FQDNs for the mail server were mail.mydomain.com.
    I set up a new DNS entry - mail2.mydomain.com - as a CNAME for mail.mydomain.com.
    On my Mac, I set up Exchange account #1 with the server set to mail.mydomain.com.
    I then set up Exchange account #2 with the server set to mail2.mydomain.com.
    Even though both FQDNs resolve to the same IP, this seems sufficient for Mac OS X to consider them as separate servers, elliminating the problems I had before when I set both Exchange accounts to the same mail server FQDN.
    I've only tried this on OS X 10.7 Lion, and the recent 10.7.1 update, although I wouldn't be surprised if the same trick works for earlier versions of OS X.

  • Old AP Invoices not showing up for a user

    Hello,
    Working on EBS:11.5.0 windows, the problem is that a specfic user can not see the old invoices while other users are able to see the old invoices. The problem has occurred yesterday, everything was working fine before that.
    Any help on this regard will be highly appreciated.
    Thank you,
    Adith

    1) Are both users who can / can not see the invoice using the same responsibility ?
    2) Any recent changes / patches moved aorund the time from which this problem is visible ?

  • Windows Services service not showing up for domain users

    When I log in with a domain account I do not see the Windows Remote Management (WS-Management)
    service, when I login as the local administrator the service is there.  Anyone know what might be causing this and how I can fix it?

    Hi,
    Have you tried to reconfigure it with the domain account?
    Installation and Configuration for Windows Remote Management
    http://msdn.microsoft.com/en-us/library/aa384372(v=vs.85).aspx
    Best regards
    Michael
    If you have any feedback on our support, please click
    here.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Looking for some one who can help me in SUN IDM

    Hi Friends,
    I am looking for some one who can help me to learn sun IDM. Off couse I will pay for your time.
    I can be reached at [email protected]
    Please let me know if you have some time
    Thx

    Hi Zebra,
    I really appreciate your reply. I would like to discuss out of this forum so that no one here annoyed with our newbie questions. Please send me email as I listed earlier to discuss best ways. I send email to Andy to join us.

  • Sun IDM training

    Hello,
    I am new to SUN IDM Product. I want to go for training in SUN IDM. I noticed there are three courses and I am confused which one to go for. The three courses I noticed are:
    IDM-4485 - Sun Java System Identity Manager: Deployment Fundamentals II
    IDM-345 - Sun Java System Identity Manager: Deployment Fundamentals
    IDM-2455 - Sun Java System Identity Manager 6.0: Administration and Maintenance
    I want to learn IDM thourughly so can someone help me which course should I go to out of these three?

    pinto_g wrote:
    Hi
    The first step into the world of IdM is
    too much work. Kid just wants "duh dumps" like all the others...

  • OpenSSO-Sun IDM integration

    Hi All,
    I have implemented the OpenSSO-Sun IDM integration based on the "OpenSSO Integration Guide.pdf". Now, if the users are created in Sun-IDM are provisioned to OpenSSO. Can anyone suggest me, can the users created in OpenSSO be provisioned to Sun IDM?
    Also, is there any way to have a password sync between OpenSSO and Sun IDM users? That is, if the user's password is changed in OpenSSO can it also be changed in Sun-IDM?
    Best Wishes,
    Aruna

    Hi Frank,
    Thanks for the response,
    1. This is user/pw from the AC system you need to send with the web service call from SUN to AC
    So, we create and provide user credentials to IDM team and they need to incorporate the user credentials when ever they are calling the web services in AC5.3 ?
    For this initial communication happening, what need to be done. Setting up SAP Jco is required in this case? Do we get involved with the configuration/development activity at IDM end?
    I could not find proper documentation on this, this leaves me in what amount of involvement I have to do as a SAP GRC AC5.3 consultant.
    Regards......

  • MB5B showing diff data for diff users

    Dear All,
    At my client side in standard report MB5B for one user data for particular material is coming while for another user
    it is showing no data.
    I have checked authorization object in SU53 but it is having no problem.
    Roles,parameters and profiles are correct in both.
    Also i have checked all materials in MB5B for both users and found the materials which are having nil stock in current
    date are not showing data for that user while for other user it is showing data.
    What could be the reason and what changes are required in user profiles??
    Thanks,
    Naren

    Thanks Ajit....in category it was not tick..
    Naren

  • Expert pls help: Sun IDM with ldap active sync

    Hi all,
    Currently i am configuring Sun IDM 6.0 SP1 to active sync with Sun directory server. I have enabled Retro Change Log but yet i cant find my changeNumber in directory server. Could anyone show me a way (search?) to get what changeNumber directory server currently running?

    Check the account used by IDM to access DS can search cn=changelog branch. If he is not Directory Manager, you probably need to set an ACI on that branch.
    HTH

Maybe you are looking for

  • Enable disk use to load songs from ipod to computer?

    I have music from a desktop and am trying to put all of that music onto my laptop by enableing the disk use. All of the songs are already stored on my ipod. I tried to press "enable disk use" but it is gray and already checked. Plus I already have "m

  • Every time i download something i get this error message "Fireclam Problem"

    Every time i download anything i get this problem once the download is completed. Fireclam Problem The program executable (null) could not be found. Make sure that ClamAV/ClamWin is installed properly and check the Fireclam settings I downloaded the

  • Programs wont open

    This week I have several programs that are quitting unexpectedly, or will not open all of a sudden.  Photoshop CS, office 2004, and even the Appleworks programs.  They all refuse to open.  I uninstalled PS, and the office products, and then tried to

  • PDF Digital Signature for Offer letter

    How to enable, pdf digital signature for BI Publisher, we need to enable for the offer letter generated thro' irecruitment . Please advice Thanks Siva

  • Dynamic actions required for IT0021 - child subtype 2.

    Hello , Can someone help me  with required dynamic actions to delimit the child subtype in infotype 21, when any new subtype is created in IT0021? Best Regards,